Threat sensor deployment and management
Various embodiments of apparatuses and methods for threat sensor deployment and management in a malware threat intelligence system are described. In some embodiments, the system comprises a plurality of threat sensors, deployed at different network addresses and physically located in different geographic regions in a provider network, which detect interactions from sources. In some embodiments, a threat sensor deployment and management service determines a deployment plan for the plurality of threat sensors, including each threat sensor's associated threat data collectors. The threat data collectors can be of different types such as utilizing different communication protocols or ports, or providing different kinds of responses to inbound communications. The different threat sensors can have different lifetimes. The service deploys the threat sensors based on the plan, collects data from the deployed threat sensors, adjusts the deployment plan based on the collected data and the threat sensor lifetimes, and then performs the adjustments.
1. A system, comprising:
a plurality of computing devices, physically located in a plurality of different geographic regions of a provider network, that have respective processors and memory to execute a plurality of threat sensors;
one or more computers with one or more processors and associated memory configured to implement a threat sensor deployment and management service of a provider network, wherein the threat sensor deployment and management service is configured to:
determine a deployment plan that specifies a collection of threat sensors across respective geographic regions of the plurality of different geographic regions, individual threat sensors configured to detect interactions from sources and comprising a plurality of different types of threat data collectors, wherein the deployment plan specifies:
a first threat sensor, of the collection of threat sensors, for a first geographic region of the plurality of different geographic regions, wherein the first threat sensor comprises:
a first type of the plurality of different types of threat data collectors comprising one or more honeypots, and
a second type of the plurality of different types of threat data collectors, distinct from the first type of threat data collector, that utilizes a different communication protocol or a different communication port than the first type of threat data collector to collect threat data, or that provides different responses to inbound communications to collect threat data;
a second threat sensor, for a second geographic region of the plurality of different geographic regions, wherein the second threat sensor comprises different types of threat data collectors to collect threat data;
a first lifetime for the first threat sensor comprising the first and second types of threat data collectors comprising one or more honeypots; and
a second lifetime for the second threat sensor comprising the different types of threat data collectors, wherein the second lifetime is different from the first lifetime;
deploy and configure according to the deployment plan the first threat sensor and second threat sensor, with respective threat data collectors, at different network addresses in the first geographic region and the second geographic region;
collect threat data from the deployed threat sensors deployed to the first geographic region and the second geographic region;
based on the collected threat data and the different lifetimes of the respective threat sensors, determine an adjusted deployment plan that specifies the first and second threat sensors for respective geographic regions, the adjusted deployment plan comprising one or more adjustments to the deployment plan; and
perform the adjustments to the threat sensors in respective geographic regions according to the adjusted deployment plan.
2. The system as recited in claim 1 , wherein the provider network provides a plurality of services including a virtual compute instance service, and wherein the threat sensor deployment and management service uses the virtual compute instance service to deploy at least some of the plurality of threat sensors.
3. The system as recited in claim 2 , wherein at least a particular one of the plurality of threat sensors not implemented by the virtual compute instance service is deployed outside of the provider network, and wherein to collect threat data from the deployed threat sensors, the threat sensor deployment and management service is further configured to:
collect data from at least the particular one of the plurality of threat sensors deployed outside of the provider network.
4. The system as recited in claim 2 , wherein the threat sensor deployment and management service is further configured to:
provide an interface for a client of the provider network to specify details for a desired threat sensor deployment; and
wherein to determine the deployment plan for the plurality of threat sensors, the threat sensor deployment and management service is further configured to:
determine the deployment plan based at least in part on the specified details from the client.
5. A method, comprising:
performing by a threat sensor deployment and management component:
determining a deployment plan that specifies a collection of threat sensors across respective ones of a plurality of different geographic regions of a provider network, individual threat sensors configured to detect interactions from sources and comprising a plurality of different types of threat data collectors, wherein the deployment plan specifies:
a first threat sensor, of the collection of threat sensors, for a first geographic region of the plurality of different geographic regions of the provider network, wherein the first threat sensors comprises:
a first type of the plurality of different types of threat data collectors comprising one or more honeypots, and
a second type of the plurality of different types of threat data collectors, distinct from the first type of threat data collector, that utilizes a different communication protocol or a different communication port than the first type of threat data collector to collect threat data, or that provides different responses to inbound communications to collect threat data;
a second threat sensor, for a second geographic region of the plurality of different geographic regions, wherein the second threat sensor comprises different types of threat data collectors to collect threat data;
a first lifetime for the first threat sensor comprising the first and second types of threat data collectors; and
a second lifetime for the second threat sensor comprising the different types of threat data collectors, wherein the second lifetime is different from the first lifetime;
deploying and configuring according to the deployment plan the first threat sensor and second threat sensor, with respective threat data collectors, at different network addresses in the first geographic region and the second geographic region;
collecting threat data from the threat sensors deployed to the first geographic region and the second geographic region;
based on the collected threat data and the different lifetimes of the respective threat sensors, determining an adjusted deployment plan that specifies the first and second threat sensors for respective geographic regions, the adjusted deployment plan comprising one or more adjustments to the deployment plan; and
performing the adjustments to the threat sensors in respective geographic regions according to the adjusted deployment plan.
6. The method as recited in claim 5 , further comprising:
performing adjustment iterations by the threat sensor deployment and management component at different times, wherein a particular adjustment iteration comprises repeating:
the collecting the threat data from the deployed threat sensors;
the determining the adjusted deployment plan; and
the performing the adjustments to the threat sensors.
7. The method as recited in claim 5 , wherein the performing the adjustments to the threat sensors according to the adjusted deployment plan further comprises one or more of: terminating a threat sensor, deploying at least one new threat sensor at new network address different from the plurality of different network addresses at which the plurality of threat sensors were deployed, or modifying the lifetime of a deployed threat sensor.
8. The method as recited in claim 5 , further comprising:
recording, by threat data collectors of corresponding ones of the deployed threat sensors, information about inbound communications received at the corresponding ones of the deployed threat sensors; and
generating, by the corresponding ones of the deployed threat sensors, threat sensor logs from the recorded actions of the corresponding threat data collectors.
9. The method as recited in claim 5 , further comprising:
responding, by a particular one of the threat data collectors of a deployed threat sensor, to inbound communications with different identifying information to simulate responses from different types of systems.
10. The method as recited in claim 5 , further comprising:
performing by the threat sensor deployment and management component:
determining that one or more threat sensors of a particular geographic region are receiving a greater number of inbound communications compared to a threshold; and
deploying, based at least in part on the determining, additional threat sensors at network addresses in the particular geographic region.
11. The method as recited in claim 5 , further comprising:
performing by the threat sensor deployment and management component:
determining that a particular threat sensor of the deployed plurality of threat sensors is receiving a larger number of inbound communications than a threshold; and
extending, based at least in part on the determining, the lifetime of the particular threat sensor.
12. The method as recited in claim 5 , wherein at least two of the different threat data collectors in a deployed threat sensor communicate on the same port using different communication protocols, the method further comprising:
performing by the deployed threat sensor:
determining an inbound communication protocol for an inbound communication; and
selecting the threat data collector of the at least two threat data collectors that communicates using the determined inbound communication protocol to handle the inbound communication.
13. The method as recited in claim 5 , wherein at least two of the different threat data collectors in a deployed threat sensor communicate on the same port using different communication protocols, the method further comprising:
performing by the deployed threat sensor:
receiving an inbound communication; and
selecting one of the at least two of the different threat data collectors to respond to the inbound communication, wherein the selection is a weight-based randomized selection, with weights given to the individual different threat data collectors.
14. The method as recited in claim 5 , further comprising:
performing by a particular one of the threat data collectors of a deployed threat sensor:
analyzing an inbound communication, wherein the inbound communication comprises a request to initiate a communication to a network address;
determining the network address present in the inbound communication; and
downloading data from the network address present in the inbound communication in order to determine information useful for threat intelligence.
15. The method as recited in claim 5 , wherein the different network addresses at which the plurality of threat sensors are deployed are not publicized.
16. One or more non-transitory computer-readable storage media storing program instructions, that when executed on or across one or more processors of a threat sensor deployment and management component, cause the one or more processors to:
determine a deployment plan that specifies a collection of threat sensors across respective ones of a plurality of different geographic regions, individual threat sensors configured to detect interactions from sources and comprising a plurality of different types of threat data collectors, wherein the deployment plan specifies:
a first threat sensor of the collection of threat sensors, for a first geographic region of the plurality of different geographic regions, wherein the first threat sensor comprises:
a first type of a plurality of different types of threat data collectors comprising one or more honeypots, and
a second type of the plurality of different types of threat data collectors, distinct from the first type of threat data collector, that utilizes a different communication protocol or a different communication port than the first type of threat data collector to collect threat data, or that provides different responses to inbound communications to collect threat data;
a second threat sensor, for a second geographic region of the plurality of different geographic regions, wherein the second threat sensor comprises different types of threat data collections to collect threat data;
a first lifetime for the first threat sensor comprising the first and second types of threat data collectors; and
a second lifetime for the second threat sensor comprising the different types of threat data collectors, wherein the second lifetime is different from the first lifetime;
deploy and configure according to the deployment plan the first threat sensor and second threat sensor, with respective threat data collectors, at different network addresses in the first geographic region and the second geographic region;
collect threat data from the deployed threat sensors deployed to the first geographic region and the second geographic region;
based on the collected threat data and the different lifetimes of the respective threat sensors, determine an adjusted deployment plan that specifies the first and second threat sensors for respective geographic regions, the adjusted deployment plan comprising one or more adjustments to the deployment plan; and
perform the adjustments to the threat sensors in respective geographic regions according to the adjusted deployment plan.
17. The one or more non-transitory computer-readable storage media of claim 16 , wherein the program instructions further cause the one or more processors of the threat sensor deployment and management component to:
perform adjustment iterations at different times, wherein a particular adjustment iteration comprises repeating:
the collecting the threat data from the deployed threat sensors;
the determining the adjusted deployment plan; and
the performing the adjustments to the threat sensors.
18. The one or more non-transitory computer-readable storage media of claim 16 , wherein to perform the adjustments to the threat sensors according to the adjusted deployment plan, the program instructions further cause the one or more processors of the threat sensor deployment and management component to perform one or more of:
terminate a threat sensor;
deploy at least one new threat sensor at new network address different from the plurality of different network addresses at which the plurality of threat sensors were deployed; or
modify the lifetime of a deployed threat sensor.
19. The one or more non-transitory computer-readable storage media of claim 16 , wherein the program instructions further cause the one or more processors of the threat sensor deployment and management component to:
determine that a threshold number of inbound communications have been received by a particular deployed threat sensor from a single source; and
prevent the plurality of different threat data collectors of the particular deployed threat sensor from responding to further inbound communications from the single source.
20. The one or more non-transitory computer-readable storage media of claim 16 , wherein the program instructions further cause the one or more processors of the threat sensor deployment and management component to:
determine that a particular threat sensor of the deployed plurality of threat sensors has been compromised by malware; and
terminate, based at least in part on the determining, the particular threat sensor.